CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5512  CVE-2002-1125  Candidate  FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5771  CVE-2002-1387  Candidate  The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.  Proposed (20030317)  ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green  Green> ACKNOWLEDGED-BY-VENDOR  View
5518  CVE-2002-1131  Candidate  Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.  Proposed (20030317)  ACCEPT(4) Armstrong, Cole, Cox, Green    View
5520  CVE-2002-1133  Candidate  Encoded directory traversal vulnerability in Dino"s web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "" (%5c) characters.  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> No confirmation available. Software apparently no longer available.  View
5521  CVE-2002-1134  Candidate  Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View

Page 28 of 20943, showing 5 records out of 104715 total, starting on record 136, ending on 140

Actions